Key Takeaways:
WEEX Crypto News, 2026-04-22 12:04:54
The Kelp DAO incident on April 18, 2026, laid bare vulnerabilities in DeFi infrastructure, resulting in over $600 million in losses. These losses stemmed from a targeted attack that minted 116,500 unbacked rsETH due to a compromised LayerZero verifier node. Security firm Halborn had previously highlighted this single-point architectural weakness, forewarning what has now become a cautionary tale of structural oversight.
In a high-stakes maneuver, the Lazarus Group—a subdivision dubbed TraderTraitor—leveraged compromised RPC nodes to carry out a DDoS attack, thereby executing a fake message that conjured the uncollateralized rsETH. The fact that no novel smart contract vulnerabilities were exploited underscores the issue: known misconfigurations were ignored.
[Place Image: Demonstration of Kelp DAO exploit via LayerZero verifier]
This flawed setup, documented and previously flagged, turned internal security oversights into a significant exploit. Attackers rapidly converted rsETH into ETH and Arbitrum, using Tornado Cash for further transactions to obscure origin trails.
DeFi’s TVL had been dwindling due to macroeconomic pressures. However, the Kelp DAO exploit rapidly escalated the situation, triggering a $13 billion capital flight within just 48 hours, according to DefiLlama. This bleached market liquidity, blindsiding even those protocols not directly linked to rsETH like Compound, which still faced withdrawal spasms.
Aave, profoundly affected, witnessed its TVL drop from $26.4 billion to roughly $18 billion—a dramatic $8.45 billion fall, mainly as a protective measure against crystallizing bad debts tied to faulty rsETH collateral.
[Place Image: Chart showing Aave’s TVL decline]
Two paths emerge from here. If Kelp DAO issues a credible forensic report along with a restitution strategy, and if Aave manages to rectify its rsETH exposure, the contagion could stabilize. On the contrary, further delays in LayerZero’s security overhaul could trigger another wave of withdrawals, forcing yield hunters to pivot to more secure yet interconnected ecosystems.
LayerZero’s naming of the Lazarus Group provides some directional insight into responsibility, yet formal affirmation is essential. Meanwhile, the DeFi community anxiously awaits comprehensive reports from both Kelp DAO and Aave. These reports will be pivotal in gauging immediate recovery prospects and long-term resilience.
The vulnerability exposed—relying on a 1-of-1 verifier—is far from unique to Kelp. Other protocols running similar frameworks must heed these warnings. An industry-wide reassessment of architectural robustness is inevitable if future misplaced trust is to be avoided.
Governance tokens feel the ripple effects too. AAVE, for instance, dipped over 20% post-exploit, primarily driven by users’ de-risking maneuvers reflecting a shaky confidence in asset-backed lending.
[Place Image: Governance token valuation trends post-exploit]
This uncharted terrain poses questions about possible protocol adaptations. Will platforms adopt multi-layered verifier structures, or are cross-chain networks fundamentally vulnerable? As stakeholders dwell on these questions, they remain wary of any incidents that might precipitate a similar exodus.
The exploit was triggered by a vulnerable single-point verifier node under LayerZero, compromised through RPC node hijacking, resulting in unbacked rsETH minting.
116,500 rsETH was minted without collateral through the exploit, roughly 18% of the circulating supply.
DeFi TVL suffered a $13 billion reduction within 48 hours of the exploit, hitting a one-year low.
Aave, SparkLend, and Fluid froze their rsETH markets, with Aave’s TVL falling by $8.45 billion.
The Lazarus Group, specifically its TraderTraitor subunit from North Korea, is suspected, but formal confirmation is awaited.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

Key Takeaways An FTX/Alameda-associated wallet moved 4.126 million ZRO tokens to market maker Wintermute, with an approximate value…

Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…

Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…













Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…



Key Takeaways: Arbitrum’s security council froze 30,766 ETH connected to a major Kelp exploit, valued at $71.2 million.…

Key Takeaways: The Kelp DAO exploiter has moved $175 million worth of Ether, part of a larger $290…

Key Takeaways: Aave’s total value locked (TVL) plunged from $26.4 billion to $17.94 billion following a massive hack.…









Key Takeaways An FTX/Alameda-associated wallet moved 4.126 million ZRO tokens to market maker Wintermute, with an approximate value…
Key Takeaways: North Korean operatives have obtained over $500 million from DeFi platforms in under three weeks. The…
Key Takeaways: The attacker moved $175 million in stolen ETH to new wallets using privacy tools. The exploit…